قانوني

Data Processing Agreement

Last updated: 1 January 2026. This Data Processing Agreement (“DPA”) forms part of the agreement between GATMEDI Ltd, trading as ClinixSummary (“Processor”, “we”, “us”) and the entity using our services (“Controller”, “You”), pursuant to the UK GDPR and EU GDPR.

1. Scope and Purpose of Processing

The Processor processes personal data on behalf of the Controller solely for the purpose of providing the ClinixSummary AI clinical documentation service. Processing activities include: receiving and processing audio recordings of clinical encounters; generating structured clinical notes, transcripts and codes; storing generated documentation in the Controller’s account; and processing account and billing information.

2. Types of Personal Data

Account Information. Name, email address, professional credentials, organisation name and billing details. Audio Recordings. Recordings of clinical encounters, which are immediately and permanently deleted upon note generation. Clinical Notes. AI-generated clinical documentation including transcripts, structured notes, codes and referral letters. Usage Analytics. Anonymised, non-PHI usage data (feature usage, session duration, error logs).

3. Data Subject Categories

Data subjects include: (a) healthcare professionals who use the ClinixSummary platform; and (b) patients whose clinical encounters are documented through the service. Patient data is processed solely as part of the clinical documentation generated from audio input.

4. Controller and Processor Obligations

The Controller shall: ensure a lawful basis for processing; provide clear notice to data subjects; and issue documented instructions for processing. The Processor shall: process personal data only on documented instructions from the Controller; ensure personnel are bound by confidentiality obligations; implement appropriate technical and organisational measures; assist the Controller with data subject rights requests; and delete or return all personal data upon termination.

5. Sub-processor Management

The Processor engages sub-processors to assist in providing the service. A current list of sub-processors is published on our Trust Center. The Processor shall provide the Controller with at least 30 days’ prior written notice before engaging a new sub-processor. All sub-processors are bound by data protection obligations no less protective than those in this DPA.

6. International Data Transfers

Where personal data is transferred outside the UK or EEA, the Processor shall ensure appropriate safeguards are in place, including the use of Standard Contractual Clauses (SCCs) as approved by the European Commission and/or the UK Information Commissioner’s Office. The Processor shall conduct transfer impact assessments where required.

7. Technical and Organisational Measures

The Processor maintains the following measures to protect personal data: AES-256 encryption at rest; TLS 1.2+ encryption in transit; role-based access controls with least-privilege principles; comprehensive audit logging of all data access; regular penetration testing and vulnerability assessments; immediate and permanent deletion of audio upon note generation; and incident response procedures.

8. Data Subject Rights

The Processor shall assist the Controller in responding to data subject requests including: access, rectification, erasure, restriction of processing, data portability, and objection. The Processor shall respond to Controller instructions regarding data subject requests without undue delay.

9. Audit Rights

The Controller has the right to conduct audits of the Processor’s data processing activities, including inspections, to verify compliance with this DPA. Audits shall be conducted no more than once annually, with at least 30 days’ prior written notice. The Processor shall make available all information necessary to demonstrate compliance.

10. Breach Notification

The Processor shall notify the Controller without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach. Notification shall include: the nature of the breach; the categories and approximate number of data subjects affected; the likely consequences; and the measures taken or proposed to address the breach.

11. Term and Duration

This DPA remains in effect for the duration of the underlying service agreement. Upon termination, the Processor shall, at the Controller’s election, delete or return all personal data and certify deletion in writing, unless retention is required by applicable law.

12. Contact

For questions about this DPA or to request execution, contact our Data Protection Officer at dpo@clinixsummary.ai.

معتمد من عملية إدارة الجودة ClinixQM